Penetration Testing in the Cloud

SOURCE Boston 2015

Presented by: Dan Lambright
Date: Wednesday May 27, 2015
Time: 10:50 - 11:30
Location: Library
Track: Security and Technology

This talk discusses challenges associated with ensuring your infrastructure is secure in the cloud. Cloud providers are very careful with letting customers run penetration tests because they can be misunderstood for real attacks, but such tests are needed to confirm data is safe. This talk discusses the conditions and limits of permissions obtainable, and explores methods of doing targeted tests in ways that will not affect others using multi-tenant hardware. A promising approach is to have a docker instance play the role of the hacker, and use an instance's internal network interface to carry out attacks.

Dan Lambright


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats